Description
A vulnerability was determined in Webkul Bagisto up to 2.4.4. Affected is an unknown function of the file /admin/customers/login-as-customer/ of the component Admin Customer Impersonation Feature. This manipulation of the argument ID causes authorization bypass. The attack can be initiated remotely. The exploit has been publicly disclosed and may be utilized. The vendor confirms: "The reported issues were already identified through our internal security assessment process prior to this notification and are being handled through our established internal security and development lifecycle. Some of these items have already been addressed, while the remaining items are planned for resolution in upcoming product releases."
Published: 2026-08-14
Score: 5.1 Medium
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A vulnerability exists in Webkul Bagisto in the Admin Customer Impersonation Feature. By manipulating the ID argument in the /admin/customers/login-as-customer/ endpoint, an attacker can bypass authorization controls and assume the identity of any customer. This allows the attacker to access personal customer information, view orders, and perform actions on behalf of the customer. The flaw is classified as an improper authorization weakness (CWE-285). The vulnerability can be exploited remotely and has been publicly disclosed, indicating that attackers may already be attempting to use it.

Affected Systems

Webkul Bagisto version 2.4.x, including all releases up to and including 2.4.4, are affected. The issue resides in the admin customer impersonation feature. No later major releases are known to contain the bug at the time of this analysis.

Risk and Exploitability

The vulnerability has a CVSS score of 5.1, indicating moderate severity. EPSS information is not available and the CVE is not listed in the CISA KEV catalog, suggesting that while the flaw is exploitable, it may not be widely targeted yet. Attackers who can access the admin interface can gain unauthorized customer access, potentially leading to data exposure and fraudulent activity. The remote nature of the attack requires that the attacker has network access to the application or can trick an administrator into executing the vulnerable action.

Generated by OpenCVE AI on August 14, 2026 at 16:26 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update Bagisto to the latest released version that addresses the impersonation flaw (any version beyond 2.4.4).
  • If an update cannot be applied immediately, disable or remove the /admin/customers/login-as-customer/ route from the application or restrict its usage to a limited set of trusted administrators.
  • Conduct an audit of all admin‑level routes to verify that proper authorization checks are in place, ensuring that only authenticated and authorized personnel can invoke sensitive customer‑impersonation actions.

Generated by OpenCVE AI on August 14, 2026 at 16:26 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 14 Aug 2026 15:30:00 +0000

Type Values Removed Values Added
Description A vulnerability was determined in Webkul Bagisto up to 2.4.4. Affected is an unknown function of the file /admin/customers/login-as-customer/ of the component Admin Customer Impersonation Feature. This manipulation of the argument ID causes authorization bypass. The attack can be initiated remotely. The exploit has been publicly disclosed and may be utilized. The vendor confirms: "The reported issues were already identified through our internal security assessment process prior to this notification and are being handled through our established internal security and development lifecycle. Some of these items have already been addressed, while the remaining items are planned for resolution in upcoming product releases."
Title Webkul Bagisto Admin Customer Impersonation Feature login-as-customer authorization
First Time appeared Webkul
Webkul bagisto
Weaknesses CWE-285
CWE-639
CPEs cpe:2.3:a:webkul:bagisto:*:*:*:*:*:*:*:*
Vendors & Products Webkul
Webkul bagisto
References
Metrics cvssV2_0

{'score': 5.8, 'vector': 'AV:N/AC:L/Au:M/C:P/I:P/A:P/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 4.7, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 4.7, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 5.1, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-08-14T15:00:08.326Z

Reserved: 2026-08-14T07:44:14.726Z

Link: CVE-2026-19834

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-14T16:16:54.437

Modified: 2026-08-14T16:16:54.437

Link: CVE-2026-19834

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-14T16:30:05Z

Weaknesses
  • CWE-285

    Improper Authorization

  • CWE-639

    Authorization Bypass Through User-Controlled Key